Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
416 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.43% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage in LookupModMask in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file with invalid virtual modifiers. | |
| Modificada | Media (5.5) | 0.54% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure. | |
| Modificada | Media (5.5) | 0.54% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage when parsing invalid atoms in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because lookup failures are mishandled. | |
| Modificada | Media (5.5) | 0.43% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage when handling invalid aliases in CopyKeyAliasesToKeymap in xkbcomp/keycodes.c in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file. | |
| Modificada | Alta (7.8) | 0.45% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | An invalid free in ExprAppendMultiKeysymList in xkbcomp/ast-build.c in xkbcommon before 0.8.1 could be used by local attackers to crash xkbcommon keymap parsers or possibly have unspecified other impact by supplying a crafted keymap file. | |
| Modificada | Media (5.5) | 0.43% | — | XkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | An infinite loop when reaching EOL unexpectedly in compose/parser.c (aka the keymap parser) in xkbcommon before 0.8.1 could be used by local attackers to cause a denial of service during parsing of crafted keymap files. | |
| Modificada | Media (5.5) | 0.43% | — | Xkbcommon Project XkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because the XkbFile for an xkb_geometry section was mishandled. | |
| Modificada | Media (5.5) | 0.43% | — | Xkbcommon Project XkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Unchecked NULL pointer usage in xkbcommon before 0.8.1 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file, because geometry tokens were desupported incorrectly. | |
| Modificada | Media (5.5) | 0.54% | — | LibxkbcommonXkbcommonCanonical Ubuntu Linux | 25/8/2018 | 17/6/2026 | Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation. | |
| Modificada | Alta (8.2) | 0.66% | — | Redhat OpenstackOpenstack Tripleo-common | 22/8/2018 | 17/6/2026 | A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with '..' and it… | |
| Modificada | Media (5.5) | 5.3% | — | Apache Commons CompressOracle Weblogic Server | 16/8/2018 | 17/6/2026 | When reading a specially crafted ZIP archive, the read method of Apache Commons Compress 1.7 to 1.17's ZipArchiveInputStream can fail to return the correct EOF indication after the end of the stream has been reached. When combined with a java.io.InputStreamReader this can lead to an infinite stream, which can be used… | |
| Modificada | Crítica (9.8) | 2.2% | — | Phpoffice Project Common | 15/7/2018 | 17/6/2026 | XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. | |
| Modificada | Media (6.5) | 0.97% | — | Mcafee Common Catalog | 7/6/2018 | 17/6/2026 | External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential information via a crafted HTTP request parameter. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestXmlbeam | 11/5/2018 | 26/6/2026 | Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does not restrict external reference… | |
| Analizada | Alta (7.5) | 1.9% | — | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data Rest | 18/4/2018 | 26/6/2026 | Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Broadcom Spring Data CommonsPivotal Software Spring Data RestVmware Spring Data RestApache Ignite+1 | 11/4/2018 | 26/8/2026 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data… | |
| Modificada | Alta (7.5) | 2.8% | — | Apache Commons Email | 20/3/2018 | 17/6/2026 | If a user of Apache Commons Email (typically an application programmer) passes unvalidated input as the so-called "Bounce Address", and that input contains line-breaks, then the email details (recipients, contents, etc.) might be manipulated. Mitigation: Users should upgrade to Commons-Email 1.5. You can mitigate this… | |
| Modificada | Media (5.5) | 3.7% | 💥 PoC | Apache Commons CompressOracle Mysql ClusterOracle Weblogic Server | 16/3/2018 | 17/6/2026 | A specially crafted ZIP archive can be used to cause an infinite loop inside of Apache Commons Compress' extra field parser used by the ZipFile and ZipArchiveInputStream classes in versions 1.11 to 1.15. This can be used to mount a denial of service attack against services that use Compress' zip package. | |
| Modificada | Alta (7.8) | 0.42% | — | Debian Postgresql-common | 5/12/2017 | 17/6/2026 | The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, in Ubuntu 14.04 LTS before 154ubuntu1.1, in Ubuntu 16.04 LTS before 173ubuntu0.1, in Ubuntu 17.04 before 179ubuntu0.1,… | |
| Modificada | Crítica (9.1) | 2.5% | — | Oracle Common Applications | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Gantt Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Common Applications Calendar | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (8.2) | 1.9% | — | Oracle Common Applications Calendar | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (5.3) | 1.9% | — | Oracle Common Applications Calendar | 19/10/2017 | 17/6/2026 | Vulnerability in the Oracle Common Applications Calendar component of Oracle E-Business Suite (subcomponent: Applications Calendar). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Media (6.5) | 0.97% | — | Jenkins Docker Commons | 5/10/2017 | 17/6/2026 | Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authenticate with a Docker Registry. This functionality did not check permissions, allowing any user with Overall/Read permission to get a list of valid credentials IDs. Those… | |
| Modificada | Crítica (9.8) | 7.0% | — | Apache Commons Jelly | 28/9/2017 | 17/6/2026 | During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to connect to said URL. This could lead to XML External Entity (XXE) attacks in Apache… |